The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Cyber Leaders
Cyber Leaders artwork

Defending Critical Infrastructure in Hot War with Tim Conway

Cyber Leaders · 2026-04-22 · 49 min

0:00--:--

Key moments - from our scoring

Substance score

78 / 100

Five dimensions, 20 points each

Insight Density16 / 20
Originality13 / 20
Guest Caliber18 / 20
Specificity & Evidence17 / 20
Conversational Craft14 / 20

The episode examines cyber operations unfolding in real-time during the US-Israel-Iran conflict, moving beyond hypothetical discussions of cyber warfare to concrete examples. Tim Conway, technical director of industrial control system security at Sands, walks through Iranian cyber targeting of critical infrastructure - including Stryker medical equipment, petrochemical facilities, desalination plants, and energy networks across dozens of sites in the Middle East, UAE, Bahrain, Kuwait, and beyond. Unlike the Ukraine conflict where cyber was one dimension among many, this war shows how offensive cyber (Israeli targeting of surveillance systems to support kinetic operations, US operations in Venezuela) integrates with military strategy. The discussion covers how attack definitions have shifted - no longer clear distinctions between military targets and critical infrastructure - and examines lessons from Stuxnet through to current supply-chain attacks like the pager operations. The key insight: geopolitical context determines how identical cyber attacks are interpreted; the colonial pipeline ransomware incident would now be treated as an act of war rather than criminal activity. CISOs and critical infrastructure defenders must understand this represents escalated, coordinated cyber-kinetic operations where nation-states now openly deploy capabilities previously held in reserve.

Key takeaways

  • →Iranian cyber actors are actively targeting critical infrastructure across the Middle East including petrochemical plants, oil refineries, water desalinization, pharmaceutical facilities, and medical equipment companies like Stryker, with capabilities degraded but still operational despite active conflict.
  • →Identical cyber attacks receive vastly different geopolitical interpretations based on context - the colonial pipeline incident would now be treated as a declaration of war if repeated during active hostilities, whereas it was previously dismissed as criminal ransomware.
  • →Cyber and kinetic operations are now coordinated and sequential in warfare: within missile range, attacks are joint cyber-physical; beyond that range, pure cyber achieves the same strategic goals of disrupting fuel supplies and public opinion.
  • →Iranian threat actors have matured from simple DDoS and wiping attacks to sophisticated misuse of industrial control system devices, progressing from targeting Israeli hardware users to broader campaigns affecting critical infrastructure control systems globally.
  • →The US offensive cyber posture shows greater willingness to employ advanced capabilities (traffic camera hacking, supply chain attacks) in direct support of military operations, burning previously reserved tools rather than maintaining them in reserve.

In this episode

  1. 1Introduction and Episode Context: New Format and Serious Geopolitical Backdrop
  2. 2The State of Cyber Operations in the Iran-US-Israel Conflict
  3. 3Critical Infrastructure Targeting: Scope, Scale, and Victims Across the Region
  4. 4Lessons from Ukraine and Evolution of Cyber Tactics in Modern Warfare
  5. 5US Offensive Cyber Capabilities and Implications for Military Strategy

Mentioned

Tim ConwayJames LyonKieran MartinSandsUK National Cybersecurity CentreStrykerColonial PipelineIranIsraelUnited StatesStuxnet

Guests

Tim Conway

Topics in this episode

Critical infrastructure cyber attacksStuxnet and nuclear program targetingColonial Pipeline ransomwareStryker medical equipment attacksIranian cyber groupsIsraeli offensive cyber operationsWater desalinization plant targetingPetrochemical and oil refinery attacksIndustrial control systems (ICS) securitySupply chain attacks (pager and radio operations)

Questions this episode answers

What critical infrastructure has Iran targeted in the current conflict?

Iranian cyber operations have targeted petrochemical sites, oil refineries, oil fields, water desalinization plants, pharmaceutical plants, medical equipment companies like Stryker, steel facilities, data centers, LNG facilities, and telecommunications networks across the Middle East and beyond, with impacts documented in dozens of locations from Azerbaijan to Norway.

How is this conflict different from the Ukraine cyber war in terms of cyber tactics?

The Iran-US conflict shows coordinated cyber-kinetic operations, instantaneous retaliation (versus delayed response in Ukraine), more mature targeting of industrial control system misoperation rather than just availability, and offensive cyber explicitly integrated into military support operations like the Israeli traffic camera hacking.

What would happen if a colonial pipeline-type attack occurred during this conflict?

It would be treated as a declaration of war, whereas the original colonial pipeline incident in 2021 was treated as criminal ransomware; identical attacks receive different interpretations based on geopolitical context and active military hostilities.

Why do nation-states avoid repeatedly using advanced cyber capabilities like Stuxnet or the pager attacks?

Once these capabilities are deployed and discovered, they are 'burned' and no longer usable - they become known to defenders, so nation-states preserve advanced tools in reserve rather than expending them repeatedly unless strategically necessary.

How are Iranian cyber groups coordinating with nation-state objectives?

Iranian cyber groups exchange targeting information, reconnaissance data, and access obtained through ransomware campaigns with state-sponsored units, with conversations about coordinated response intensifying after the Ukraine invasion showed how criminal and state operations intertwine during wartime.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

16 / 20

The episode delivers substantial, concrete insights about cyber operations in active conflict - particularly the progression of Iranian tactics from denial-of-service to operational technology manipulation, the blurred lines between criminal and state-sponsored activity, and the cascading risks of tool sprawl in critical infrastructure. However, it contains lengthy introductions and some repetition that dilute density; not every minute is packed with novel claims.

They could have just as easily changed all the logic and changed what was happening within that process to cause manipulation, cause misuse. They were on the same device. They had admin-level access. They could have done a lot of things, but they didn't.
We're building all of those paths. And now we get to a point where if an adversary can get an initial access into that space, they can ride over all those same paths.

Originality

13 / 20

The episode provides fresh context by examining a live, ongoing conflict (Iran-Israel-US) through a cybersecurity lens rather than theoretical frameworks. However, the core defenses and attack patterns discussed (spear phishing, lateral movement, supply-chain pivots, tool exploitation) are well-established playbooks. The main originality lies in applying known threat models to an active hot war with real-time observations rather than novel attack types or defensive approaches.

This is a war. But even if we get back to a gray zone, the capabilities of Iran will probably recover. So more of that striker type of event will happen.
the demarcation between kinetic and cyber, the kind of moment a ceasefire is struck is much more clear and kinetic than with cyber. And I think your warning that this will, you know, continue in retaliation and may even result in a higher run rate of attack in business as usual in years to come

Guest Caliber

18 / 20

Tim Conway is exceptionally well-calibrated for this episode: he is the technical director of ICS security at SANS, has direct experience defending critical infrastructure during the Ukraine conflict, and brings decades of hands-on operational knowledge. His answers reflect real-world decision-making (cost-benefit trade-offs on segmentation, understanding tool sprawl consequences) rather than theoretical posturing. He is a rare combination of technical depth and policy-operational experience.

the technical director of industrial control system security at Sands, who has more experience of protecting critical infrastructure than basically anyone else alive, and has worked on cybersecurity in the context of war in Ukraine to tremendous positive effect
for even those of us who've been working in this area for nearly three decades, when that happened, we started stepping back and looking at the complexity of doing that across supply chains

Specificity & Evidence

17 / 20

The episode excels in naming specific incidents (Stuxnet, Saudi Aramco 2012, Sheldon Adelson casino attack, Albania 2022, Stryker medical device hack, Colonial Pipeline 2021, Shamoon campaigns) and detailing technical specifics (admin-level access to water treatment devices, Microsoft Intune password compromise, firmware corruption attacks on smart meters, specific OT device impacts). Real data points and timelines anchor claims; however, some broader claims about attack scope ("dozens" of sites) lack granular detail.

they didn't even deploy any malware, they logged into Microsoft Intune
They impacted sort of the operator's screen. So they caused a loss of view and a loss of availability because the operators couldn't directly operate. But on that same device where they basically just did a website defacement from the 90s

Conversational Craft

14 / 20

The hosts ask substantive follow-up questions (on offensive cyber strategy, the evolution from Stuxnet to modern tactics, tactical progression within the war) and Tim is pressed to clarify nuance (the difference between device-level access and actual destructive capability, the cost-benefit trade-offs in segmentation, how different threat actors compare). However, the episode lacks productive disagreement or host skepticism; questions are generally confirmatory and hosts rarely push back on claims. The lengthy introduction, while context-setting, reduces conversational dynamism.

Fascinated by your reference to the implications of rising gas prices in the US, the price of the pumps, the reference to colonial pipeline. I sometimes wonder what would happen, what would the political implications be if there was a colonial pipeline type operation against the US right now
They may not be the most bleeding edge, but they're in the club in terms of efficacy and engagement and thoughtfulness of some sorts, right?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

cyber47back28infrastructure25critical24perspective23attacks23across21long19conflict18james17iran17capability17point16side15seen15groups14

Episode notes

In this special episode of Cyber Leaders , Ciaran and James are joined once again by Tim Conway, Technical Director of Industrial Control Systems Security at SANS, to discuss the ongoing conflict in Iran. As three of the world’s most potent cyber actors clash militarily, Tim shares his expert insight on the cyber dimensions of the conflict, the real-world risks for cyber defenders, and how best to protect critical infrastructure in an increasingly volatile geopolitical landscape. Contact: Have questions or comments? Email us at cyberleadersnetwork@sans.org

Full transcript

49 min

Transcribed and scored by The B2B Podcast Index.

You're listening to Cyberleaders. I'm James Lyon, and I've spent more years than I care to admit buried in malware samples and hunting down the bad guys online. One might say proudly a nerd. And I'm Kieran Martin.

My world's been more the policy and operational side of cybersecurity, including building the UK's National Cybersecurity Centre from the ground up. Definitely not a nerd. But between the two of us, James and I cover the technical and the strategic. That's kind of the point.

Cybersecurity is too important and too complex for just one perspective. That's right, Kieran. This show is brought to you by Sands, where we both work, and it's made for the people carrying the weight out there in the community. See those security directors and frankly anyone else in a leadership role trying to defend their organization.

We're here to cut through the noise, share what actually works, challenge what doesn't, and help you move a little bit faster and smarter on the things that matter. And it's a first today, James. New introduction, but it's quite a serious backdrop to this episode. Yeah, a double first in a way, although with the introduction, probably a triple first, but one first we're very happy about.

The other, well, maybe less happy. In an ideal world, no. I think we'd better explain what we're on about here, James, for being as cryptic as an Ening machine powered by Claude Mythos. I like that reference, that's superb.

I do think the Claude Mythos discussion is one for another day, though, Kieran. It is, yes. Uh, we better get to that soon. Yeah.

But look, here are the two new things we're doing today. First, the good news. It is an absolute pleasure to bring back one of the absolute stars of a previous episode of the show. That's the legendary Tim Conway, the technical director of industrial control system security at Sands, who has more experience of protecting critical infrastructure than basically anyone else alive, and has worked on cybersecurity in the context of war in Ukraine to tremendous positive effect, and who it is a pleasure to have back on the Cyberleaders podcast.

Yeah, absolute pleasure to have you back, Tim. I recall fondly our debate about the relative ascetic beauty of nuclear power stations or the wilderness. And I remember which side of the discussion you were on. Welcome back, Tim.

Thank you again for having me, which I cannot believe you brought me back. Here I am, and I'm pleased to be here. And James, the uh worked in this space more than anyone alive makes me feel extraordinarily old. And I'm 150 in about a month, so I'm already feeling pretty old.

Well, you're our first guest to appear for a second time, but I'm afraid it's extraordinary reasons that brings you back, isn't it, James? It is indeed. And I Kier and I should say up front, we promised Tim last time we'd bring him back for something fun. Yeah.

So in advance, um sorry, Tim. But that brings us to the second reason. This is a special episode to discuss the role of cyber in some extraordinary events. So that's the other first we're talking about.

When Tim, Kier, and I were talking about the beauty of critical infrastructure and hard plants and all that, we were talking about how to protect the essential public services and such infrastructure from, well, the face of a tumultuous geopolitical world. And so now we're talking about it again in this special episode, but not hypothetically anymore. Indeed, James, as everyone knows, at the end of February, war broke out with the bombings of Iran by the United States and Israel, and then the subsequent missile attacks by Iran on, well, a range of regional neighbors.

Now, I guess we should be clear when we're talking. It's early to mid-April, and we're in the early part of the fragile ceasefire announced by President Trump and Pakistani intermediaries and the Iranians themselves. So this episode will bring it to you as quickly as possible. But by the time it comes out, who knows what the next few days, weeks, and months will bring.

But given how important geopolitics and the associated risks are for cyber defenders across this wonderful network of listeners and contributors, we wanted to bring Tim back, not on a happy occasion, but on this much more serious one, to discuss what we're learning so far as three of the world's most potent cyber actors clash militarily. And one of them, the Iranians, of course, lashes out directly against Western digital targets. That's true, Kieran. We might produce this episode and find that we have to reproduce it several times with changing events.

Now, look, no one is saying this conflict is or was, I guess we don't yet know, primarily a cyber war. But this network and this podcast is about learning, and there are cyber dimensions to this conflict which understandably haven't been given as much of an airing as other topics. I also think there's some more world firsts layered in here, and much of the world's military powers have watched as some of those firsts have played out. Absolutely, James.

And while it should be time to bring Tim in, we obviously on this podcast have a tradition of very long introductions. So I'm going to lengthen it further, but not for the typical reasons of just us being a little bit on the long-winded side. I think it's important to set out the facts insofar as we can tell what they are about cyber in this conflict. And I think there are three points.

First, in Iran, we're dealing with an established, capable set of actors who really specialize in destruction. We'll come to it later, but since 2012, if not before, they've had a history of wreaking havoc on Wall Street, in US critical infrastructure, in Gulf critical infrastructure, in mainstream US businesses, even in Europe. They have a long history of doing disruptive cyber attacks outside of wartime. They know how to prey on the weak points, they know those vulnerabilities between enterprise and operational technology systems that can stop them from working.

So that's the first point. Second, while this isn't a cyber war, cyber is part of it. The United States have been more than usually open about their own cyber operations this year, both in Iran and Venezuela. But if we focus on the threat from the Iranian side, they have capabilities.

Now those capabilities are probably degraded. This is, after all, a war. Some of the infrastructure of the state-based hackers, the best of the bunch, if you like, the most threatening, some of their infrastructure will be destroyed. Some of the non-state hackers will be in hiding.

Some of them will be suffering from the internet blackouts that the regime have imposed on the rest of the country. But that being said, however degraded they may be, the Iranian hackers are still active. Yeah, they're doing some intimidating type stuff, propaganda stuff like hacking the FBI director's old Gmail to embarrass the US government. They're sending horribly unpleasant and intimidating messages to Iranian dissidents based in the US.

But fundamentally, they're about wrecking things, and they still have enough capability to, for example, cause a shortage of medical equipment, not just in the United States, but beyond in the wider Western world, by hacking Stryker, the well-known medical services company, a critically important company for global medicine and global surgery. And they're offline in one of those classic political geopolitical attacks that looks like ransomware without a ransom. So the second point is there are operations here, there is a threat.

And the third is the long-term uncertainty, which may lead to a heightened threat. Look at what Iran can do when it's been degraded. Now no one knows, as you've said, James, we may have to update this podcast because we're here at a moment in time. But there doesn't appear at this point in time to be any version of the final outcome of this war that's going to be anything other than highly tense in the long term.

So we're not in the gray zone now. This is a war. But even if we get back to a gray zone, the capabilities of Iran will probably recover. So more of that striker type of event will happen.

There will almost be a prize, for example, from the Iranian perspective, for causing the sort of chaos that criminal hackers caused in the United States with the colonial pipeline hack in 2021. Because what is the ultimate economic webbing right now? It's fuel shortages. So even if the cyber war hasn't cut through that much so far, we are probably in this for the long term.

Tim, would you agree with that? It is a wonderful summary. And uh I would agree 100% that um when colonial happened, we treated it like, hey, this is criminal ransomware groups. They didn't understand that the response from a safety perspective was going to impact liquid natural gas delivery.

They were going after data. There was that assumption. But there was other groups that looked at this as, yeah, but to kind of fog a war, those adversary groups work with nation-state groups and exchange information. So any information collected in a ransomware campaign is passed for future targeting, access, all of the above.

And after the Ukraine war started, those conversations were immediately front and center. How would we respond differently if the colonial pipeline event happened again? Before it was kind of a shoulder shrug. Ah, those Russian ransomware extortion criminals going after money.

Naughty Russians. If it happened post-invasion of Ukraine, it would have been viewed very, very differently. And right now, at the peak of this conflict with Iran, if that same attack happened now, 100% would be treated as declaration of war. Same events, same cyber capabilities, same targets, same adversary groups, treated completely different because of the geopolitical situation.

Well, thank you, Tim, for agreeing with me after that lengthy monologue you had to endure. I have to say, given your expertise, I'm rather relieved you agreed with me. But let's get started with you. You're the guest, you're the expert.

Now, some of these questions may overlap with that monologue, but I wanted our listeners, and perhaps people who may be listening who follow this less obsessively than the likes of Yumi and James. I wanted them to have a clear picture of what's been happening so far. But at the risk of repetition, why don't you set out in your own words what's been happening? Yeah, I would say difficult questions get difficult answers, uh, complex.

But um, I think uh both of you, from the perspective of this audience and leaders around the world working in governments, working in critical infrastructure, I think it's important to kind of divide this up and not look at it from a perspective uh to your statements earlier on a is this specifically a cyber war? And is there cyber attacks as a retaliatory or a commensurate response? I think we are now in a state where kind of cyber digital is embedded in all elements of military conflict and any expanding geopolitical conflict.

So everything is on the table from the perspective of independent commercial entities, government sites, anything that can be targeted to sort of cause some level of societal chaos or act as a deterrent. As you kind of look at the targets going against uh oil and the impacts, the gas prices here in the US on a daily basis. That is what is being talked about is the price of the pump constantly. From a perspective of impacting those types of critical infrastructure and those types of feeders into that market, that is what is getting the attention, even less so than sites that are being targeted or military objectives or impacting nuclear uh weapons development.

The news is being led by the price of the pump. So, from a Iranian perspective, if you can impact that by targeting different sites, impact that by targeting critical infrastructure, that is absolutely fair game and it will start to add deterrence and sway public opinion long, long ago. And both of you have been working in this space for a very long time. Yeah.

I imagine a lot of CISOs who are a member of this network have been working in this space for a long time. And going way back, there were very, very kind of established statements on hey, an attack on critical infrastructure is a declaration of war. Yeah. And in the US from the Clinton era, that was statements from White House.

Attacks on critical infrastructure will not be tolerated, and they are a declaration of war. Discussions across NATO from early attacks in Estonia in 2007, in Georgia in 2008 that involved some telecommunications impacts, involved some electric, involved some oil. There were discussions immediately of if this occurred in NATO countries, would this be in Article V? All of those things were happening.

And it was very, very defined kind of line in the sand. And even I'll I'll say it now once, but I'm certain it's going to come up again just because of where we are, the Stuxnet events. Yeah. And kind of the discussion of, hey, how do we start to determine whether that was a military target or whether that was sort of commercial power and energy targets that are critical infrastructure?

Where do those two things overlap? And is it an attack on critical infrastructure? Or was back then the Natans facility a military strategic target? So the definitions have been blurring of what is an attack?

What was the intent? Who was the attacker? Were they state sponsored? Was it criminal?

Kind of pulling in what happened in colonial pipeline. Was that state sponsored? Uh, was it just criminal financial gain? And how do we respond?

Those things have shifted. And I think in recent times, cyber attacks, critical infrastructure, they are just part of the target list. And, you know, this long list of this conflict that has begun between US, Israel, and Iran has now spread across UAE, Bahrain, Kuwait, Qatar, Jordan, Oman, Saudi, and uh Iraq. And then as you look across, I've been running this list of my own different uh critical infrastructure sites that have been impacted.

And it's grown to the point of telecommunications, petrochemical sites in the dozens, oil refineries in the dozens, oil fields, water desalinization plants, like absolutely impacting human health, pharmaceutical plants, steel facilities, data center, LNG. The list is massive. And kind of in the 20, 30, 40 different sites and locations, even in areas outside of the conflict zone, from a pipeline in Azerbaijan to uh sites in Norway, anything that has to do with kind of these critical sectors that can suade public opinion.

And if it's in the immediate zone, you can assume physical and cyber will be jointly used, coordinated. If it's beyond where missiles and rocket capability can strike, it's going to be pure cyber to achieve the same goal. Yeah, Tim, it's fascinating, isn't it? I mean, we've spent years on this podcast talking about what might happen when a major cyberpower goes to war.

And, you know, everything you're describing now, we don't really have to hypothesize anymore. But it's a pretty fascinating laundry list of different happenings and not just the kind of early hours of the conflict where, you know, there were prayer apps being hijacked for kind of PsyOps operations and hijacking of traffic cameras. I mean, the Supreme Leader being tracked by his own city's traffic cameras, it sounds like a spy novel, and yet it's something that's that's actually played out here.

Also interesting that Iran made some pretty interesting mistakes here, but they've been in the cyber game since 2010, 2011, longer than most CISOs have been in their current jobs. No snide remarks intended there on CISO longevity. But you know, Tim, given that we've now had several major wars recently, most obviously the long-running horrors of Ukraine. Are we learning anything comprehensively about all of this?

Are there marked similarities or differences between the cyber dimension of Iran and Ukraine? Has it moved on in some notable ways we should pay attention to? Yeah. So definitely both events have highlighted absolute focus on critical infrastructure targets and kind of the uh the overlap of when conflict begins, critical infrastructure targets are absolutely in scope, um, through physical, through cyber, through coordinated, as they impact a nation's capability, their communications, their power to feed critical sites.

So they're 100% targeted. I I can remember even as long ago as the Iraq war, some of the teams that went in when they saw sites and they needed to sort of occupy, and they just took the approach of taking them out through physical kinetic methods, and then the amount of time, effort, and energy that was spent in rebuilding and reconstructing and the amount of American lives that were lost in that effort and Allied lives, because they're less defended, less protected while they're up reconstructing transmission lines and power plants.

So ideally, the ability to sort of disable through a cyber means and then turn back on without the long kind of restoration and rebuild efforts and all of those things. Cyber has long been a desired capability for any nation to develop for a conflict. And time has passed, and now we've seen that across the Russia-Ukraine war. We've seen it here, we've seen it in a number of different places with uh Venezuela and the impacts to kind of power system there joint with uh the operation that occurred in that country.

Just looking across many, many locations and seeing this kind of nexus of cyber and physical operating together. The one thing that I will say, looking across, there's some parts of this that you sort of like, yep, this is exactly what would have predicted in this type of thing with a response from Iran on the cyber side with DDoS attacks, wipers. But there are some unique things that are starting to occur, like we've seen with Stryker, and where we've seen progressions from some of the cyber attacks that occurred on critical infrastructure that tied back to the October 7th events.

When that occurred, some of these Iranian groups went after water treatment facilities and water pumping stations in many nations, going after anybody who was using Israeli hardware or Israeli devices. And what the scope and the intent of those attacks were has now progressed into a broader campaign that's, you know, kind of being talked throughout across all the US now with specific control system devices and control system targets, where it's not just making those devices unavailable.

They've matured in attacks to misusing those devices and potentially causing misoperation and damage. The between what I would say we can learn, meaning US, UK, people joining this call, the variations in the retaliation and aggression and commensurate impacts. So early days in 2022, 2023, out of the attacks in Ukraine, they were much a defensible position and looking for allies and ally support and continuing to provide and sort of sustain capabilities across the country. And it wasn't until late where retaliatory actions started to begin in that conflict.

Here, retaliation was instantaneous. And you're seeing multiple impacts across the region, cyber, physical, uh, all of the above. I think in both areas, what you're seeing from lessons learned in drone capability and communication attacks, GPS, SATCOM, uh mobile device, Intel, sort of disinformation campaigns. This is definitely at a more elevated level than what we saw in the early stages of the Ukraine-Russia conflict as well.

Wow. So things are absolutely progressing. Okay, there's so much to pick up on there, Tim, particularly on the defensive side, and I'm sure we'll spend most of our time on that. Fascinated by your reference to the implications of rising gas prices in the US, the price of the pumps, the reference to colonial pipeline.

I sometimes wonder what would happen, what would the political implications be if there was a colonial pipeline type operation against the US right now that actually led to shortages. But we'll come back to that. I want to spend a little bit of time just asking you about, from the US perspective, and obviously you're in the US, about the offensive side. So to frame this, let's start with your reference to Stocksnet.

Fascinating observations on to what extent that was regarded as a military target. But the other thing about Stocksnet was that the essence of Stocksnet was to prevent the need to go to war. It was to say, look, we don't have to bomb the nuclear facilities because we can degrade it using cyber. But in this operation, James has already mentioned the apparent Israeli hacking of traffic cameras to prepare the attack on the late Ayatollah Khameni.

You've referenced Venezuela. The president in his own inimitable communication style referred to what he called the discombobulator, which had unknown but apparently helpful effects in helping to land US forces in the dark of night in Caracas. So it seems that there is, on the face of it, a more aggressive use of offensive cyber in the context and the support of military operations by the US. I guess my question is, is that your impression?

And if so, did it surprise you? And are there any implications of a more militarily aggressive posture in offensive cyber from the United States? Before you answer that, Tim, I do just have to note, Kieran, I think um on the discombobulator, murky discombobulator is another potential candidate for a threat name we need to get into our show notes. Well, absolutely.

And maybe Tim will tell us what the discombobulator was. But yeah, what are the implications? And are were you surprised? I will speak nothing of that device.

So as uh as I think of you as my audience, I don't think anything about this is surprising at all. Meaning, yeah, when Stuxnet uh occurred and the ongoing concerns of a nuclear program and around for over two decades, and you sort of looked at if something were going to impact that in any way, even now with the conflict that's occurring, being able to completely take that down and take that risk off the table, that is almost impossible to do simply from error and simply from uh cyber.

There needs to be some level of boots on ground, people working with them, kind of doing the right thing and going in and obtaining it's very, very well protected and defended. Back during the uh Stuxnet era, that was a pure play cyber physical uh kinetic impact that I think was new and novel and sort of an exquisite attack that most were not aware of uh from a capability perspective, or they certainly weren't thinking that way. Once that was sort of publicly understood and known, I think a number of people, like those of us on this call and CISOs that are joining, have now put that in the realm of capability understanding in their mind.

But then since then, we've seen significantly less complex attacks having impacts on companies around the globe. So there's this realization that in the realm of possible, there's some very, very advanced things that we became aware of during the Stuxnet days. Um, we've sort of worked on at national labs and demonstrated in conferences and seen at uh proof of concept research events. And then we've seen them in the real world where kind of understanding this nexus of Capabilities and where that integrates with cyber.

And you see long campaigns like the pager and radio attacks. That was something that for even those of us who've been working in this area for nearly three decades, when that happened, we started stepping back and looking at the complexity of doing that across supply chains and tracking and communicating and knowing that once that capability was burned and you used it once, it's gone. And now, so kind of your catalog or your library of capabilities, just like Stuxnet, once it's used, it's gone.

So from a nation state perspective, you're not going to want to burn those over and over and over again if you don't need to. Of course. And with so much critical infrastructure and so many of the organizations that are listening to this call, they don't need to be that complex. They don't need to be that exquisite, kind of from a capability perspective, to achieve a result from a cyber and certainly not from physical.

With low price point entry drones that can have a significant package carry weight and some physical impact in the region, there's a lot of things that can be done at a very, very basic level. And then the corollary to that from a cyber perspective as well, where some of the attacks that we're seeing, they're using cybersecurity tools against organizations. Yeah. So the people who are doing all the right things and going out and investing and building maturity into their environments, now they've added tools not just for themselves, but also for the adversaries.

So, Tim, that brings us nicely to the issue of Iran's attack capability in cyberspace. This isn't their first cyber war rodeo. They've not been in a full-scale war with the US until you can argue last year, but certainly this year. But they were hacking Wall Street back in 2012.

They were hacking Saudi Aramco, causing devastation to that strategically crucial company in 2013, when the late American billionaire Sheldon Edelson made a very belligerent speech advocating strikes in Iran in 2014. He found his casinos wiped out. And you mentioned NATO and Article V and declarations and thresholds of war. As recently as 2022, the government of Albania was brought to its knees because it was hosting an anti-Iran dissident group at the request of the US, and cyberattackers affiliated with Iran destroyed lots of government networks, and the Albanian government was so badly damaged they considered going to the rest of NATO and saying that they'd suffered an act of war.

So given all of that, and given what we've known about the Iranian threat actors, how would you assess their capability going into the war? Who are they? And what sort of things do they do that we should have been worrying about already? Yeah, I think from that perspective, and I'd be interested to hear both of your comments on this, especially on the IT side, where a tremendous amount of activity that Iranian groups have been focused on has been loss of availability.

So impacting from DDoS attacks, impacting data, impacting systems and access from uh wiper campaigns. That has been going on for a very, very long time. So that means from a capability perspective, they're doing things that are relatively predictable for initial access. So large use of spear phishing campaigns for initial access, eventually progression into targeting perimeter devices and known vulnerabilities where they could sort of start using a perimeter device as a pivot point, and some interesting things where not necessarily going direct after target, but going after second-order effects.

So going to a third party and hopping through a third party, doing some research, going to a third party that has connections into a target. So contractors and construction companies and vendors or providers so they could get to their actual target and simply pivoting. So those initial access campaigns, those have been things that we've been seeing for over a decade from groups in this space. Not necessarily to the level of the typhoons, the uh salt typhoon, vault typhoon, linen typhoon from a complexity and maturity in infrastructure, not to the complexity and maturity of what we've been seeing from bespoke packages being created from uh Russian adversary groups and shared across attacker campaigns.

Definitely more in line with sort of uh who I would compare, uh, say in North Korea from that perspective on the IT side, on the OT side and the intent to sort of in the early Shamoon campaigns, moving from, hey, can we live in this IT space and remain undetected so that we could then use it to pivot into the OT space, which is our actual target. So going after, again, from an oil, from an industry perspective, those were viable targets and getting into their operations networks so they could cause longer-term outages there, not just in their IT networks where it's impacting data, but instead using that environment to live in to pivot down and go after specific operational areas to cause kinetic effect.

That is a unique area that we've started to see them move into, in some cases, earlier than others, like North Korea and other adversary groups. So on the IT side, I don't think it's anything surprising. I think it's fairly well understood over the last decade where we've been seeing them move on more industrial targets and having impacts, um, kind of leading the way from other adversary groups. I wouldn't say leading the way from Russia or from China, but definitely from North Korea and other kind of activist groups around the globe.

They're in the club, aren't they, Tim? They may not be the most bleeding edge, but they're in the club in terms of efficacy and engagement and thoughtfulness of some sorts, right? Yes, of course. Again, you can almost still see them learning, whereas some of the OT systems that they've impacted, like let's talk about the October 7th stuff, the things that were happening to the water treatment sites, the devices that they were going after, the level of access that they had in those devices and what they did, they impacted sort of the operator's screen.

So they caused a loss of view and a loss of availability because the operators couldn't directly operate. But on that same device where they basically just did a website defacement from the 90s, where they changed the operating screen so there was nothing that the operator could see or use, they could have just as easily changed all the logic and changed what was happening within that process to cause manipulation, cause misuse. They were on the same device. They had admin-level access.

They could have done a lot of things, but they didn't. And so you questioned, did they understand where they were and what they could do? And now you've seen them progress to that level in the warnings that are coming out across the US for electric, for water, for a number of critical infrastructure here, in that they have made that progression of if we're here, we can go change what this environment is doing and manipulate it to achieve an effect. So you see them sort of developing on target and progressing over time.

Whereas, for example, uh Russia, by the time we were aware of capabilities to impact safety systems, they were already out in the wild and occurring. And we weren't even talking about that at proof of concept events, at black hats, DEF CONs teaching it in courseware. It was already being used and exploited in the wild on specific targets that could have impacted just about any process environment in the world. Yeah.

A quick little underline in here, and then I got a follow-on question for you. I think for those listening, when you think about nation states and you listen to how you described their focusing, their evolution of tactics and what they're doing, it's very tempting. I find myself doing it sometimes, to quickly frame them into this incredibly capable high-tech persona. But I think what's interesting about you're describing is it's a lot of description of effectiveness and how they think about their targets doesn't necessarily come with high-tech or high capability in terms of execution.

I know we'll get to this a little bit later, Tim, and you can correct my messy description of this, but Handler, who uh you know, associated with a number of attacks, including the attack on Stryker, and took responsibility for it, you know, Department of Justice formally attributed them to Iran's military and intelligence and security division. But you know, they didn't need a zero day in that particular very sizable attack. They needed a password. So, you know, I'd love every CISO listing to kind of let that sink in and make sure as we think about this stuff that it doesn't necessarily have to be the case we conflate high-end capability and targeting of these more complex environments with geopolitical goals with high-end capability.

And in this instance, they didn't even deploy any malware, they logged into Microsoft Intune. Tim, this might actually be the ultimate living on the land attack of all time. But but yeah, we we'll come back to that in a moment because I'd I'd love to get you to walk us through what CISOs could learn from it. And isn't it living off the land?

Have I caught you out on something technical, James? Did I say living on? I'm afraid you did. That will not be edited out.

Oh, it's my desire to pivot into farming. I just don't want our CISO listeners at a time of crisis thinking that there's some crazy new technique that they didn't know anything about that sounds the exact opposite of what they need to worry about. When you live off the land and you combine it with AI, then you get living on the land. It's a t-shirt waiting to happen.

Okay, just for the avoidance of direct listeners, that's not true. Anyway, back to the somber war. Back to the somber war. How has the war affected these capabilities that you know you're describing here?

I mean, have these folks working directly for the state or through these kind of franchise connections been affected, presumably have been affected, by the bombings of key state offices? Are those with a kind of looser connection to the state affected in the same way? Are they affected by this massive internet blackout where it's very hard to get connectivity at all? Have we seen any major shift in tactics as the conflict has evolved?

Yeah, I I think it would be silly to assume that from a cyber capability that they haven't been affected, meaning loss of communications, loss of access, just daily life, even if you are kind of going in nine to five and this is your day job, uh, facilities that you'd be going into in some cases have been disrupted, power has been impacted, uh, certainly your communications are limited. If you're a hacktivist group, uh loosely affiliated with government, um, loosely affiliated with IRGC, again, you're living a life, you might have a family.

Of course, you're impacted by what's happening in country, and that's going to limit time and focus to go retaliate and do a number of things. I think the things that are absolutely capable that don't require that are some of the physical attacks and some of the physical elements. And that's where you haven't seen a slowdown. That's where you've seen a retaliatory commensurate response happening across the entire region, targeting critical infrastructure, targeting impacts, impacting power and water, sort of at that similar level of if this happens to us, this is what we're gonna do globally to impact the world.

The more this sort of calms down from a physical kinetic impact, you're gonna see a rise in cyber being reintroduced. And I don't think that's going to end even after a regime change, even after kind of conflict ends. We're creating sort of uh a generation-long level of retaliation and sort of impact, especially from a cyber perspective, I believe, that uh is gonna go on for some time, just in a similar aspect to what's gonna happen if we ever get to a build back better and war is over in Ukraine and Russia.

What this has done across those two countries and other countries and the surrounding areas to families and to people, this is going to be a long, ongoing, maybe non-state sponsored but retaliatory sort of uh strikes. And to the degree that it can be done with little cost and it can be repeatable and target multiple areas, that's where cyber is a perfect fit. So I think uh as we start to draw down on the kinetic and physical impacts, you'll start to see a continued rise in cyber.

And of course, that will sort of correlate to increases in uh internet and communication restoration and power stability. And then we'll get back to sort of where we were with Russia and China for years of attacks that are coming from those nations. To what degree are they complicit as a country and allowing that from happening? And then to what degree does that start to spark additional geopolitical conflict because they're allowing those types of criminal groups or hacktivist groups to operate within their nation and not bringing them to justice?

Let alone with any gentle encouragement they might offer. Just the space to operate is dangerous enough. Of course. And Tim, it's interesting.

I'd not really thought as clearly about it until you were describing it there, but the demarcation between kinetic and cyber, the kind of moment a ceasefire is struck is much more clear and kinetic than with cyber. And I think your warning that this will, you know, continue in retaliation and may even result in a higher run rate of attack in business as usual in years to come, I think is quite likely. But to add an example there, Tim, tell us a little bit about Stryker and you know, CISA's general kind of warning of targeting of water and energy in the US.

Firstly, what happened? And is this the type of thing we might expect to see more of? Absolutely. So if you think about any classroom you've ever found yourself in, James, and people that you've talked to from a CISO perspective, and you think of all the great things we've done and sort of trying to add controls and build frameworks and strengthen companies and really try to balance that where are you going to spend the $1 you have and the CIS critical controls and the top five ICS controls and all the things where we're trying to help companies shape programs and where they're just asking, just tell me what to do.

And you think about every one of those steps of, hey, you got to make sure you're doing backups. And then you pause for a second and say, well, wait, so if we're doing that across a thousand substations, we certainly don't have backup systems and servers at every one. That means we are opening up firewall rules, we are allowing systems to go talk to central locations to perform backups. So we're opening paths, trusted paths.

Then we're installing agents, and then we're doing the same thing for monitoring and for alerting and for change management and for asset management and for asset health. All the things that we will tell CISOs and everyone listening, go do this to improve your cybersecurity. We're building all of those paths. And now we get to a point where if an adversary can get an initial access into that space, they can ride over all those same paths.

And it's not necessarily that they're targeting solar winds. It's not necessarily that they're targeting Microsoft or Intune. It's that they're targeting a tool that you've connected to everything that you care about. So they care about that tool.

And what we have now kind of from a, if you're a large multinational company, the tool sprawl that you're facing is absolutely massive. And the sort of siloed people who I work on this tool or I work in this space, and that's what I do without understanding sort of what that means organizationally or operationally or how that could be misused is become very, very complex where it may not even be truly understood what could happen. And if you look to Stryker and you see, well, sure, we've integrated and we have a federated user model and we have active directory spread across and we're we're using it at plant floor and we're using it across corporate so we can have authentication and accountability, even down to the plant floor, look at all the great things we've done.

Awesome. And then when that's misused and devices are wiped, you're not operating anymore. But if you step back from that and say, okay, now CISO, how would you prevent this from happening to you? Well, sure, you're gonna have a different active directory for this line at this facility and a different for this line at this facility, and you're gonna have directory segmentation and you're not gonna allow them to talk.

And then they look at that and say, across all the countries we operate, that's gonna cost us $30 to $60 million to go deploy and support and do. And now we have this even more complex environment. So it's this discussion of after the event happened for Stryker, for example, what do we go do? How do we rate limit device wipes?

From a utility perspective, we looked at the same thing. Hey, we're gonna go deploy four million smart meters. Awesome. All of our customers got it.

Now, what if an adversary gets in and through our meter data management system pushes a corrupt firmware? And that firmware forces all the meters to open the latch and everybody's power goes off. That creates a frequency issue, causes power generation to trip offline, cascading event, and it can happen from a very simple system that we put in place. So how do we limit that from happening?

Well, if we limit it, that's a software control, meaning an adversary can overcome it. So how do we have to limit it from an architecture perspective? Multiple compaths, well, that's going to cost a ton of money across every service territory. If you're a company that's water, gas, and electric, that's three different meters.

So the overall interconnectivity and interdependency that we've driven to has created very complex environments. The biggest thing that you would ask kind of this audience is do you understand those interdependencies and interconnectedness? And what are your greatest high-consequence events that you cannot live with? And if you can answer those questions, then you can start to work with your engineering and operations teams to design around it and operate through an attack.

Yeah, Tim, I think that makes a massive amount of sense. And of course, what is really interesting here is that some of the seemingly most mundane attack tactics and in some ways mundane targets can then lead to kind of outlandishly sized and quite scary ramifications for kind of life and limb and everyday life. But I will point out for those listening, again, not to be a kind of drumbeat on this, the sister advisory around Stryker and the kind of various issues and how you'd avoid it.

I mean, it reads like the greatest hits of things we've been telling people to fix for a decade. Patch of systems use multi-factor authentication, don't leave industrial controllers on the open internet. Personal favorite of mine. I think the advice hasn't much changed.

But the reality seems to be that it is then hard to actually get that done and get it done comprehensively enough on scale to not present these attackers with significant opportunity. But I think from what you're describing here, the advice hasn't changed. The urgency of applying it meaningfully has. The piece that I would highlight from the CISA report is those are written.

So, number one, when you see something that's coming out from multiple agencies, badged as multiple agencies, that should immediately drive a little bit more attention. When you see it from multiple countries, even more so. But in this case, looking at it, I would say it's abstracted from the nuances and context of all the different targets. So in some cases, we're going to sound like we're talking out of one side of our mouth and in other cases from another, meaning that it almost comes off as schizophrenic, like, hey, get those get the PLCs off the internet.

Well, of course. And there are absolutely some small municipalities, some cooperatives, some manufacturing sites that that is a legitimate problem, where what they're doing for port forwarding, what they're doing for the perimeter firewalls is very, very weak. It's not great. And some devices are directly accessible and can be modified and impacted, of course.

But that same kind of a scope of could an adversary get into the IT networks, pivot down, find a data historian, pivot down, pivot down, get to an engineering set of tools and modify, and their source is coming across the internet? Sure. So is that get your devices off the internet statement still accurate? Absolutely.

But it's to a completely different degree. And what you're looking at then is segmentation and detection and various controls, different remote access and MFA. But it's still that statement in that report is sort of asking the asset owners and the operators to understand their environments, how they're supported, how they're accessed remotely, and looking at areas where they can get to those engineering tools to modify uh operations. So, Tim, that's an excellent answer.

Some really practical and specific tips on the sort of tools that people need to be thinking about to counter this threat. But because we're running out of time, sadly, we could talk about this all day of the unenviable task, or maybe the easy task, as it's just teeing up James, to try to take us back to the big picture, but to get us to a point where we have actionable takeaways for our listeners. Now, thankfully, we reached a stage early in this podcast. And I always tell you to get the state and government, particularly in a crisis, get an agreed analysis of the problems and the threat and the prognosis going forward.

And we did that early on. Then we've got into some of the details of what's happening on the offensive side, what threats people need to be aware of. You've given some very specific tips and examples, but James will want to ask the big question. So over to you, James, for the software and all this.

So, Tim, I think we're going to break show protocol here. You know, normally we have this wonderful smooth transition to my favorite bit of the show, but I think Kieran's question is much the point and it probably fits my very favorite 30-second takeaway. Although, again, to break the rules, given that we're you know merging your last question with a 30-second takeaway, I'm going to allow you 42 seconds, is after all the answer. So, Tim, what I'd love you to talk to, if you wouldn't mind, what are the takeaways here for cyber defenders, for operators, for businesses?

I mean, there's all this going on. You've predicted that the next few years are likely to see a greater volume of retaliation attacks, more of what we've seen here, even if the war ends tomorrow. So I'd I'd love you to take you know 42-ish seconds and give some advice to those who may be subject to these types of attacks. And frankly, for those who aren't, to be able to learn from these relatively high priority events and how they might better prioritize their security controls.

I'll go very tactical first and I'll just talk fast to get tactical and strategic. But the tactical side, the uh CISA alerts, the events that happen to Striker, don't look at those as company specific. Don't look at those as kind of a Rockwell PLC specific issue or even a US specific. This is an opportunity for everyone to learn the types of devices that do cyber to physical impacts any controller, any system, not just Rockwell, not just Rockwell protocols.

The targeting of those in US and beyond in critical infrastructure, that is something everyone needs to stand up and pay attention to. So looking at that alert and not just shrugging a shoulder like, oh, well, this is US. We're safe over here in UK. Or, hey, this is Rockwell, we're doing real good here because we're on a semen system.

I would very much read into that as this is tactics that are easily modified regardless of location and controller or device. The other piece that I would say that is more kind of uh strategic forward looking is with what's happening at Iran and what we expect to continue to happen from a cyber perspective, don't lose sight of the salt typhoons and the bolt typhoons of the world and the things we've been worrying about for the last three years. Those haven't gone away, those haven't stopped.

This is just in addition to that. So all of that sounds bad and scary. On the good side, look towards the human capability development, how you can pre-position systems before an attack happens against your environment. Look to detect and threat hunt.

Understand your conservative and emergency operations and how you can sort of restore system integrity. The main thing from a good news perspective, enable and equip, kind of and count on the dedicated men and women who defend critical infrastructure every day from lightning strikes, tornadoes, squirrels, rodents, cyber attacks, drones, all of the above. They are focused on delivering reliable operations. It's what they do for their careers.

We are all blessed to have them in those roles. They need assistance, they need resources, and that's where CISOs and leaders come in. I agree wholeheartedly, Tim. And I think related to the theme of our episode, Kieran and I will now promptly put you in for the Nobel Prize of Brevity.

I assume there's one of those, and Kieran and I are never going to win it. I would note on the end here as well, you know, we mentioned at the top of our show today the Enigma machine. Obviously, some incredible mathematics and technology involved in breaking that. But for the record, it was partly cracked because the operators got lazy with their key settings.

Some things in cybersecurity never change. So I do like your closing advice there that we pay attention to the basics and who's doing the work and don't assume all of this is necessarily high-tech. It just requires day-to-day focus and kind of hygiene work. Kira, over to you.

And against a difficult backdrop and a lot of challenges for cyberleaders, and obviously a very concerning time for everybody trying to make ends meet as prices go up and worrying about contagion and spread of conflict and so forth. I did like the way that for cyberleaders, you finished on a number of upbeat notes. One is relying on human capital, and the other is even though there are lots of other threats out there, you mentioned the Chinese state-sponsored typhoon operations and so forth, so much of what you're recommending is done in organizations can mitigate all of those threats and not just this specific one.

So, Tim, you did an impossible task condensing advice for cyberleaders in this extraordinary situation into such concise and actionable words. So thank you so much for coming back on the show. And do come back again. We promise you a happy episode at some point.

Next time. Next time. If you've ever seen Saturday nive when they have repeat visitors, they get to a point, I think, after your third episode where you're fourth, you get a jacket. So you guys are going to come up with a members-only jacket from the 80s with some patch or a symbol with the number of attendees.

Well, you're on the top of the leaderboard right now. And not only have we seen Saturday Night Live, they've just launched a British version. I don't think the Prime Minister likes it very much, but I guess that's kind of the point. Well, we have to leave it there.

That's it. Okay, Erin, can I just suggest that the jacket is branded with living on the land? Okay, anyway, get back to your point. We'll get back to the point, and we hope that there has been some levity amidst this somber backdrop.

But that's it for this special episode. You can leave us feedback at the podcast site. You can email us at cyberleaderspodcast at sans.org.

If you're on the podcast site or any of the other sites, leave us a rating. Apparently, it really helps. And with that, thank you very much for listening. Yes, thank you for listening.

And keep cybering from me, Kieran Martin. And me, James Lyne, it's goodbye. And please try and keep your industrial controllers disconnected from the internet if you can.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Credibility, not Likelihood [The Industrial Security Podcast]The Industrial Security Podcast · on Colonial Pipeline ransomware86 / 100

More from Cyber Leaders

All episodes →
  • The Rise and Fall of Conti with Geoff White97 / 100
  • Defending with the Same AI That’s Coming for You with Chris Cochran80 / 100
  • She Convinced the Pentagon to Let Hackers In. Legally. With Katie Moussouris92 / 100
  • Still Getting Cloud Wrong. Here’s what to Fix. With Simon Vernon89 / 100
  • The Weakest Link in a Global Life Sciences Company? People. With Dr. Kevin Jones88 / 100
Explore the best B2B Ops podcasts →
All Cyber Leaders episodes →